ak.schema.account_data_encrypted_value.v1
ak.schema.account_data_encrypted_value.v1 · file: schemas/account-data-encrypted-value.schema.json Principal-private Account Data value committed client-side. Services validate and store this envelope but never receive the account secret or plaintext.
* $ · object
Principal-private Account Data value committed client-side. Services validate and store this envelope but never receive the account secret or plaintext.
* schema ·
const "ak.schema.account_data_encrypted_value.v1"enum:
"ak.schema.account_data_encrypted_value.v1"* version ·
const "1.0"enum:
"1.0"* aead_profile ·
const "ak.aead.xchacha20_poly1305.v1"enum:
"ak.aead.xchacha20_poly1305.v1"* key_ref ·
stringpattern:
^sha256:[0-9a-f]{64}$* nonce ·
stringpattern:
^[A-Za-z0-9_-]{32}$* ciphertext ·
stringpattern:
^[A-Za-z0-9_-]{22,}$* aad · object
* schema ·
const "ak.schema.account_data_encrypted_value.v1"enum:
"ak.schema.account_data_encrypted_value.v1"* version ·
const "1.0"enum:
"1.0"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* account_data_key ·
stringpattern:
^ak\.[A-Za-z0-9._:-]+$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/account-data-encrypted-value.schema.json